GRC & Privacy Analyst

thriveglobal

United States

On-site

USD 115,000 - 125,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Mission-Driven Impact
Career Growth
Human-Centric Culture
Competitive Compensation
Health & 401(k) benefits
Thrive Time PTO

Job summary

Thrive Global is seeking a detail-oriented GRC and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization.

This role will require mastering frameworks such as SOC 2, ISO 27001, ISO 27701, HITRUST, HIPAA, GDPR, and NIST RMF while leveraging AI tooling to streamline evidence review and

Qualifications

  • Experience with GRC automation and IT security/privacy controls.
  • Experience applying HIPAA and GDPR requirements in a regulated data environment.
  • Ability to manage audits across multiple frameworks and coordinate with stakeholders.

Responsibilities

  • Administer and optimize compliance automation like Vanta.
  • Lead and support audits across frameworks with internal and external teams.
  • Maintain programs mapped to SOC 2, ISO 27001, ISO 27701, HITRUST, NIST 800-53, and AI RMF.
  • Interpret HIPAA/GDPR requirements and ensure compliant data handling.
  • Conduct risk assessments and track remediation efforts.
  • Use project management to drive timelines and deliverables.
  • Leverage AI tools to improve evidence review, policy drafting, and reporting.

Skills

GRC expertise
Vanta
Audit management
HIPAA & GDPR
AI tools adoption
Communication
Certifications (CISA, CIPP)
Healthcare data security
AI governance

Education

CISA
CIPP
ISO 27001 Implementer

Tools

Vanta

Job description

Founded by Arianna Huffington in 2016, Thrive Global is a leading behavior change technology company with the mission to improve productivity and health outcomes – one Microstep at a time. Thrive helps individuals and organizations improve well-being, performance and mental resilience with its AI-powered behavior change technology platform. Thrive’s Microsteps – small, science-backed steps to improve health and productivity – have been adopted by employees at more than 230 organizations in over 160 countries, from frontline and call center workers to executives at multinational companies. For more information, visit www.thriveglobal.com.

Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

How You’ll Contribute
  • Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring and evidence collection.
  • Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors.
  • Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF).
  • Interpret and apply privacy standards including HIPAA and GDPR, ensuring data handling practices meet regulatory obligations.
  • Conduct risk assessments, track remediation efforts, and manage evidence and control documentation.
  • Apply project management discipline to compliance initiatives — setting timelines, coordinating cross-functional owners, and driving deliverables to completion.
  • Leverage AI tools to improve efficiency in evidence review, policy drafting, risk analysis, and reporting workflows.
Qualifications & Skills
  • Demonstrated experience with GRC and compliance automation applications, particularly Vanta.
  • Working knowledge of key security and privacy frameworks: SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
  • Strong understanding of privacy regulations, including HIPAA and GDPR.
  • Proven experience managing or supporting audits and applying structured project management practices.
  • Comfort and fluency with AI tools and a willingness to integrate them into daily workflows.
  • Excellent written and verbal communication skills, with strong attention to detail.
  • Relevant certifications (e.g., CISA, CIPP, ISO 27001 Implementer).
  • Experience in a healthcare, wellness, or otherwise regulated data environment.
  • Familiarity with AI governance and emerging AI compliance requirements.

What We Offer:

  • Mission-Driven Impact: Be part of a company that’s truly making a difference in people’s lives around the world.
  • Career Growth: Develop within the company and help shape our growth strategy.
  • Human-Centric Culture: Thrive in a supportive environment with a range of wellness perks and benefits.
  • Competitive Compensation: Enjoy a comprehensive and rewarding total compensation package.
  • Health & Financial Benefits: Medical, dental, and vision coverage plus a 401(k) program with company match.
  • Time to Recharge: Generous paid time-off programs designed to help you rest, reset, and recharge — including Thrive Time, a benefit unique to Thrive that gives employees additional paid time off after major projects or intense periods of work to truly recharge and recover.

Compensation:

Total target compensation for this role will be $115,000 - $125,000.

  • Please note: We provide a competitive mix of salary, performance bonus, and equity. The final offer amount will depend on factors like experience, expertise, and may differ from the range above. This range also excludes additional benefits, such as 401(k), and medical, dental, or vision insurance.

Thrive is deeply committed to creating a safe and welcoming work environment free of discrimination and harassment so that all employees can bring their whole selves to work.

Thrive is proud to ensure equal employment opportunity (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, disability, genetics, gender, gender identity, gender expression, sexual orientation, age, marital status, family or parental status, veteran status, or any other characteristic protected by applicable federal, state or local law.

Thrive is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. Please inform Thrive’s Recruiting team if you need any assistance completing any forms or to otherwise participate in the application process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC & Privacy Analyst
GRC & Privacy Analyst

Thrive Global • United States

On-site
USD 115,000 - 125,000
Health & dental coverage
401(k) with company match
Generous paid time off
GRC & Privacy Analyst
GRC & Privacy Analyst

Thrive Global • Northern (KY)

On-site
USD 115,000 - 125,000
Thrive Time
Health & dental benefits
401(k) with company match
+2
Senior Software Engineer (Identity)
Senior Software Engineer (Identity)

Rippling, Inc. • Northern (KY)

Hybrid
USD 170,000 - 200,000
401(k) with company match
Medical, dental, and vision coverage
Thrive Time (extra PTO)
Lead Data Analyst
Lead Data Analyst

thriveglobal • United States

On-site
USD 145,000 - 175,000
401(k) with company match
Medical, dental, and vision coverage
Thrive Time paid time off
Lead Data Analyst
Lead Data Analyst

Thrive Global • United States

On-site
USD 145,000 - 175,000
Medical, dental, and vision coverage
401(k) with company match
Thrive Time - extra PTO after major s/
+1
Chief of Staff, Strategic Health Partnerships
Chief of Staff, Strategic Health Partnerships

thriveglobal • United States

On-site
USD 130,000 - 160,000
Mission-Driven Impact
Career Growth
Human-Centric Culture
+3
Lead Data Analyst
Lead Data Analyst

Thrive Global • Northern (KY)

On-site
USD 145,000 - 175,000
Health & dental coverage
401(k) with company match
Thrive Time
+1
GRC & Privacy Compliance Lead (AI-Driven)
GRC & Privacy Compliance Lead (AI-Driven)

thriveglobal • United States

On-site
USD 115,000 - 125,000
Mission-Driven Impact
Career Growth
Human-Centric Culture
+3
GRC & Privacy Compliance Specialist
GRC & Privacy Compliance Specialist

Thrive Global • Northern (KY)

Hybrid
USD 115,000 - 125,000
Thrive Time
Health & dental benefits
401(k) with company match
+2
Chief of Staff, Strategic Health Partnerships
Chief of Staff, Strategic Health Partnerships

Thrive Global • Northern (KY)

On-site
USD 130,000 - 160,000
Thrive Time (paid time off)
Medical, dental, and vision insurance
401(k) with company match
+1